Website security scope

Understand the boundary before sharing data.

This page describes the marketing website and its fictional browser demo. It is not a security certification or a claim about a production campaign platform.

The interactive demo

Demo records are fictional. Searches, review states and sample drafts are handled in the page while it is open. Reset or reload clears those demo changes. The demo does not send messages, process payments, submit filings or contact an AI service. Use fictional examples only, never personal, donor, voter or confidential information.

The contact form

Submitting the form sends your inquiry to this website’s contact endpoint. It checks required text fields, email format and a hidden spam field. When delivery is configured, the endpoint forwards the inquiry to BlueRoots through Resend. Without delivery configuration, or when the provider reports a failure, it returns an unavailable response rather than a successful submission.

The contact handler has no database-writing implementation. This does not establish how hosting infrastructure or an email provider retains logs or messages. Do not include confidential campaign records, payment details or credentials in an inquiry.

Analytics and external services

This website build contains event-label hooks but no installed analytics provider. Those labels do not themselves send visitor information to a tracker. Hosting-level logging, any future analytics setup and the handling of external sign-in destinations must be evaluated separately. We do not infer their policies from this website code.

What this page does not establish

  • No SOC 2, ISO certification or independent security audit is claimed.
  • Production encryption, access controls, tenant isolation, backups, retention and incident-response commitments require separate evidence.
  • Input validation and a spam field are limited safeguards, not proof of comprehensive abuse prevention.
  • A public demo is not a secure place to test real campaign data.

Before evaluating a live service

Ask who can access records, which providers receive them, how corrections and exports work, what retention rules apply, and how incidents are handled. Confirm those answers against the proposed agreement and demonstrated system, not the sample interface.

Read the existing privacy policy and terms. This technical description does not replace those documents or legal advice.